Researchers: flaws in Bumble exposed info of ~95M Bumble users, including Facebook data of some, and it took over 200 days after being notified to fix the bug
Thomas Brewster / Forbes :
Context & Ripple Effects
This story sits in a run of researcher-disclosed API and web bugs hitting consumer apps: Forbes' Thomas Brewster reports flaws in Bumble exposed data of roughly 95M users — including some Facebook-linked data — and that Bumble took over 200 days after notification to close the hole. The remediation clock is the story: when a comparable bug in fertility app Glow's forum exposed ~25M users' data, fixing it took about a week.
The Facebook angle echoes a familiar pattern. Researchers later documented that Facebook had known for years about contact-importer exploits that enabled scraping at 533M-user scale, and its 2018 breach left 50M accounts vulnerable to takeover. Bumble drawing on Facebook data means its exposure surface partly inherits the platform's.
First-order effects
- Data of ~95M Bumble users was exposed while the bug stayed open for over 200 days after researchers flagged it, putting Bumble's security response process — not just the flaw itself — in question.
Second-order effects
- Every dating app built on social-graph imports now faces the same researcher playbook, and Baidu's separately reported leak of sensitive user data in apps with ~1.4B downloads shows the audit wave is not platform-specific.
Third-order effects
- If disclosure-to-fix time becomes the metric researchers and press rank vendors on — a week versus 200 days — slow responders will face structural pressure to adopt fixed remediation windows, and regulators get a ready-made yardstick for negligence claims.
The trend: Independent researchers are turning consumer-app API flaws into a recurring accountability beat where speed of remediation, not mere exposure, separates the defended from the negligent.